Vulnerability Disclosure Policy
At Supernote, we take the security of our products and services seriously. We appreciate the efforts of security researchers and the wider community in helping us maintain a high level of security. This policy outlines how to report vulnerabilities to us and what you can expect in return.
Scope
This policy applies to all Supernote products, services, and digital assets, including but not limited to:
- Supernote devices
- Supernote applications
- Supernote cloud services
- Supernote websites
Reporting a Vulnerability
If you believe you've discovered a security vulnerability in any of Supernote's products or services, please report it to us as soon as possible. To report a vulnerability:
- Send an email to security@supernote.com with the subject line "Vulnerability Report"
- Provide a detailed description of the vulnerability, including:
- The affected product or service
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Any additional information that might be helpful
We kindly request that you:
- Do not exploit the vulnerability or reveal it to others until it has been resolved
- Do not use the vulnerability to access, modify, or delete data that isn't yours
- Act in good faith and ethically
Our Commitment
When you submit a vulnerability report, you can expect that we will:
- Acknowledge receipt of your report within 15 business days
- Let you know if we can confirm the vulnerability you reported
- Keep you informed about what we're doing to fix it and any problems or delays we might face while solving the issue. For simple software vulnerabilities, we expect to fix them within 90 business days. For complex vulnerabilities, please allow more time.
- Notify you when the vulnerability has been fixed
Recognition and Rewards
While Supernote does not currently offer a bug bounty program, we deeply appreciate the efforts of security researchers. We may offer public recognition for significant findings, with your permission.
Legal Safe Harbor
Supernote will not pursue legal action against individuals who submit vulnerability reports provided they:
- Comply with this policy
- Do not engage in malicious or destructive acts
- Do not violate any other applicable laws
We reserve the right to modify this policy at any time. For the most current version, please visit our website.
Thank you for helping keep Supernote and our users safe!